CVE-2023-39915CWE-232CWE-240

Crashes on parsing certain invalid RPKI objects

High · published September 13, 2023

CVSS v3.1
7.5
EPSS
1%
Percentile
41.9
In the wild
Unconfirmed
What it is

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00515 · 41.9th percentile
Weaknesses
CWE-232 · Improper Handling of Undefined Values; CWE-240 · Improper Handling of Inconsistent Structural Elements
Published
2023-09-13T14:20Z
EPSS history
Timeline
  • 13 SEP 14:20Z
    Crashes on parsing certain invalid RPKI objects
    cvelistv5